A vulnerability described as problematic has been identified in tigroumeow Media Cleaner Plugin up to 7.0.3 on WordPress. Affected is the function
get_urls_from_html. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-4912. The attack can be executed remotely. There is not any exploit available.